ci(scorecard): adopt standards scorecard-reusable wrapper#34
Merged
Conversation
Replace the standalone OSSF Scorecard job with a thin wrapper around hyperpolymath/standards scorecard-reusable.yml, matching governance.yml. - Pinned to the estate-canonical standards commit 861b5e9 (same as governance.yml) so the estate moves in lockstep. - Grants security-events:write + id-token:write on the calling job: for a reusable call the caller is the ceiling for the called token, so without this the reusable's SARIF upload is silently downgraded and fails. - Keeps the MPL-2.0 header, existing triggers, and the concurrency guardrail. - Leaves scorecard-enforcer.yml standalone (it owns the score-threshold gate and the SECURITY.md / pinned-deps checks the reusable does not cover). Supersedes the scorecard portion of the closed, stale PR #30 (which relicensed these files to PMPL-1.0-or-later against #33 and pinned an older standards SHA). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01AHygjxRyU3WwmXEhA9KF5L
hyperpolymath
marked this pull request as ready for review
June 24, 2026 08:55
|
🔍 Hypatia Security ScanFindings: 42 issues detected
View findings[
{
"reason": "Belt.Array deprecated -- use Array (12 occurrences)",
"type": "deprecated_api",
"file": "/home/runner/work/empty-linter/empty-linter/src/core/TextTransform.res",
"action": "module_replace",
"rule_module": "migration_rules",
"severity": "high"
},
{
"reason": "Js.Array2 deprecated -- use Array (1 occurrences)",
"type": "deprecated_api",
"file": "/home/runner/work/empty-linter/empty-linter/src/core/TextTransform.res",
"action": "search_replace",
"rule_module": "migration_rules",
"severity": "high"
},
{
"reason": "Js.String2 deprecated -- use String (9 occurrences)",
"type": "deprecated_api",
"file": "/home/runner/work/empty-linter/empty-linter/src/core/TextTransform.res",
"action": "search_replace",
"rule_module": "migration_rules",
"severity": "high"
},
{
"reason": "Belt.Array deprecated -- use Array (11 occurrences)",
"type": "deprecated_api",
"file": "/home/runner/work/empty-linter/empty-linter/src/core/ByteDetector.res",
"action": "module_replace",
"rule_module": "migration_rules",
"severity": "high"
},
{
"reason": "Js.Array2 deprecated -- use Array (2 occurrences)",
"type": "deprecated_api",
"file": "/home/runner/work/empty-linter/empty-linter/src/core/ByteDetector.res",
"action": "search_replace",
"rule_module": "migration_rules",
"severity": "high"
},
{
"reason": "Js.String2 deprecated -- use String (25 occurrences)",
"type": "deprecated_api",
"file": "/home/runner/work/empty-linter/empty-linter/src/core/ByteDetector.res",
"action": "search_replace",
"rule_module": "migration_rules",
"severity": "high"
},
{
"reason": "Belt.Array deprecated -- use Array (2 occurrences)",
"type": "deprecated_api",
"file": "/home/runner/work/empty-linter/empty-linter/src/core/PathHandler.res",
"action": "module_replace",
"rule_module": "migration_rules",
"severity": "high"
},
{
"reason": "Js.String2 deprecated -- use String (13 occurrences)",
"type": "deprecated_api",
"file": "/home/runner/work/empty-linter/empty-linter/src/core/PathHandler.res",
"action": "search_replace",
"rule_module": "migration_rules",
"severity": "high"
},
{
"reason": "Belt.Array deprecated -- use Array (6 occurrences)",
"type": "deprecated_api",
"file": "/home/runner/work/empty-linter/empty-linter/src/bindings/Deno.res",
"action": "module_replace",
"rule_module": "migration_rules",
"severity": "high"
},
{
"reason": "Js.Array2 deprecated -- use Array (2 occurrences)",
"type": "deprecated_api",
"file": "/home/runner/work/empty-linter/empty-linter/src/bindings/Deno.res",
"action": "search_replace",
"rule_module": "migration_rules",
"severity": "high"
}
]Powered by Hypatia Neurosymbolic CI/CD Intelligence |
1 task
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Summary
Converts
.github/workflows/scorecard.ymlfrom a standalone OSSF Scorecard job into a thin wrapper aroundhyperpolymath/standards/.github/workflows/scorecard-reusable.yml, mirroring howgovernance.ymlalready delegates to the estate's reusable workflows. Scorecard was the remaining read-only check still carrying a per-repo copy.This salvages the one genuinely useful idea from the now-closed, stale PR #30 — but done correctly on top of current
main:PMPL-1.0-or-later(reverts #33)MPL-2.0standardspin5a93d9d(older)861b5e9— same commitgovernance.ymlpinscontents: readonly → SARIF upload would failsecurity-events: write+id-token: writeon the calling jobmain, conflictingmain, cleanscorecard-enforcer.ymlThe triggers (
branch_protection_rule, dailyschedule,workflow_dispatch) and the estate concurrency guardrail are preserved, so runtime behaviour is unchanged.timeout-minutesis intentionally omitted — it isn't a permitted key on a reusable-calling job; the reusable owns its own timeouts.Type of change
How has this been verified?
scorecard-reusable.ymlexists inhyperpolymath/standards@861b5e9and that itsanalysisjob declaressecurity-events: write+id-token: write(hence the matching grant on the caller).yq:name, triggers, jobpermissions, and theuses:reference all resolve as intended.Notes for reviewers
main(patch-equivalent toe49bdfd/e036fb7), so nothing else from it is needed.hypatia-scan.ymlis not included here: despite its top-of-file "Thin wrapper…" comment, it is still the full standalone scanner onmain. Converting it is a larger change (gitbot-fleet phase, SARIF converter, PR-comment + gating policy) — happy to do it as a separate PR if you want the estate fully consistent.🤖 Generated with Claude Code
https://claude.ai/code/session_01AHygjxRyU3WwmXEhA9KF5L
Generated by Claude Code